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I In this paper, we present a quantum strong coin flipping protocol. In this protocol, an 

EPR pair and a quantum memory storage are made use of, and losses in the quantum 

^ communication channel and quantum memory storage are all analyzed. We obtain the 

(~| bias in the fair scenario as a function of p, where p is the probability that the particle 

Qj in Bob's quantum memory storage is lost, which means our bias varies as the degree of 

I losses in the quantum memory storage changes. Therefore we call our protocol semi-loss- 

^ tolerant. We also show that the bias decreases with decreasing p. When p approaches 0, 

j^ the bias approaches 0.3536, which is less than that of all the previous loss-tolerant pro- 

F^ tocols. Details of both parties' optimal cheating strategies are also given and analyzed. 

^^ What's more, experimental feasibility is discussed and demonstrated. 
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1 Introduction 



'""J Coin flipping(CF) is a cryptograpliic primitive which was firstly introduced by Blum in 1981 [T] . 

t^^ Its goal is to enable two mutually distrustful and spatially separated parties, usually referred 

^— ^ as Alice and Bob, to generate a random bit whose value cannot be controlled by any one of 

I them. That is to say, if both parties are honest, the generated bit must be or 1 with the 

|V same probability -^i while even if one party is dishonest, it is guaranteed that the outcome 

• ^ cannot be biased to or 1 with probability 1 by the cheater. Strong CF(SCF)[2l[3lH[5l [6], 

p% the most common form of CF, requires that a dishonest party, denoted by X, can by no 

^4 means improve the probability of any value of the bit to be greater than Px — \ + ex- While 

in a weaker form, which is called weak CF(WCF) [3 13 [9], both Alice and Bob have their 
preferred outcomes which are opposite and known to each other, and it is required that a 
dishonest X cannot improve the probability of his or her preferred outcome to be greater than 
Px = ^ + ex- The parameter ex , which is called the bias of X, quantifies the security of a 
CF protocol and it must be strictly less than ^ , in which case a cheater cannot totally control 
the outcome. The less e = max{ej^,eB) is, the securer the protocol is. When we say a CF 
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2 Semi-loss-tolerant strong coin flipping protocol using EPR pairs 

protocol is fair, we mean the biases for both parties are equal, i.e. ca — £b- A CF protocol 
is said to be perfect iff ea = ^b = 0. 

Even though there are many classical approaches dealing with coin flipping tasks, their 
security is all under the assumption of the complexity of a computational task(many of which 
may be efficiently solved by a quantum computer in the future). Given unlimited computa- 
tional power, a cheater can always bias the probability of any outcome to 1, so unconditional 
secure coin flipping cannot be realized by classical means. 

In the quantum settings, unconditional secure coin flipping is possible to some degree. 
Although the results of Meyers [TUI and Lo, Chau [TT] implied the impossibility of perfect 
quantum CF, there exists quantum CF that can help limit the bias to be strictly less than ^ 
In retrospect, a lot of progress has been made along the way of exploring the protocols with 
smaller bias. The first quantum SCF protocol was provided by Aharanov et al. [5] with a bias 
of 0.354[ll]. Then Spckkcns and Rudolph devised a protocol with a bias of 0.309[T2]. Subse- 
quently Ambainis [3 and, independently, Spekkens and Rudolph pi cut this bound down to 
0.25. Later Colbeck jSj proposed a protocol with the same bias 0.25, but it uses a conceptually 
different approach compared with previous ones. Rather than being built on bit-commitment, 
this protocol works by attempting to share entanglement between two parties, and then ex- 
ploiting the resulting quantum correlations to implement a coin toss. Furthermore, their 
protocol requires only qubits for its implementation, whereas bit-commitment based proto- 
cols cannot achieve such a bias without using higher dimensional systems. Unfortunately, 
Ambainis proved that any protocol with a bias of e must consist of at least ri(logloge^"'^) 
rounds of communication j3j. Then it was proven by Kitaev 13j that any quantum SCF pro- 
tocols cannot enjoy a bias less than 0.207, which has now been saturated by Chailloux and 
Kerenidis's protocol [6] based on Mochon's result [9]. With respect to WCF, Spekkens and 
Rudolph p] firstly introduced a family of protocols with a bias of 0.207 and Mochon then 
pushed this bias down to 0.192 [^ and finally to arbitrary e > [9]. In addition, quantum 
SCF and WCF have also been studied in the multiparty scenario [M] , multioutcome scenario 
[mile], and in both [milH]. 

In spite of great progress mentioned above, there is a common limit of early results: prac- 
tical issues were not taken into account. Under imperfect practical conditions such as losses 
and noise in the quantum channel or in the quantum memory storage, most protocols will 
totally fail and the bias e can exactly reach ^ T5]. Therefore, some authors have proposed 
random bit-string generation instead of single-shot coin flipping p!5]. However, this is not 
interesting from a quantum cryptographic perspective because the same goal can be achieved 
with purely classical means [19j . 

As the most prevalent practical imperfection in the long distance communication, losses 
were firstly analyzed in devising new practical protocols. In 2008, Berlin et al. [20] (see also 
Ref. lU]) introduced a loss-tolerant SCF protocol with a bias of 0.4. Before long Aharon et al. 
[2^ presented a family of loss-tolerant quantum SCF protocols which achieved a smaller bias 
than Berlin et al. [501 at a small rate. Recently, Andre Chailloux ^23j presented an improved 
loss-tolerant quantum SCF protocol with bias 0.359, by extending Berlin et al.'s protocol with 
an encryption step. 

In this article we present a semi-loss-tolerant protocol, which is different from the previous 
loss-tolerant ones mainly in three aspects: 
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1. An EPR pair instead of a qubit is employed to implement the protocol, helping guarantee 
our protocol semi-loss-tolerant when trying to push the bias down. 

2. A quantum memory storage is used and losses in it is taken into account. 

3. We find our bias varies with the change of the losses degree of the quantum memory 
storage, while the bias is independent to the losses in the quantum channel. This proves 
that there exist CF protocols that are sensitive to losses in the quantum memory storage. 

The rest of the article is organized as follows. In Sec. 2, we give the definitions of loss- 
tolerance and semi-loss-tolerancc. And in Sec. 3, we present our protocol, while details of 
the two parties' optimal cheating strategies and their maximal biases are obtained in Sec. 4 
and 5. In Sec. 6, we obtain the fair scenario by adjusting the value of the free parameter in 
the protocol. Then some experimental issues concerning the realization of a reliable quantum 
system implementing our protocol are discussed in Sec. 7. Finally, we make a conclusion and 
summarize our novelties in Sec. 8. 

2 DEFINITION OF LOSS-TOLERANCE AND SEMI-LOSS-TOLERANCE 

We say a protocol is loss-tolerant iff it is impervious to any type of losses, including quantum 
communication channels, measurement devices and quantum memory storage, this definition 
can be seen in Ref. [2U] . Therefore, protocols in Ref . [201 HH US] sue all loss-tolerant because 
they are impervious to losses in the quantum channels and measurement devices, the only 
places that losses may occur in their protocols. 

Consider another case, in which the protocol isn't impervious to certain types of losses, 
but its security varies with the degree of the losses. In other words, the protocol is sensitive to 
the loss degree of some devices, but with which they are not completely broken like many early 
protocols. We call this loss-sensitive protocol semi-loss-tolerant. It is clear that the feasibility 
of this kind of protocols is guaranteed by sufficiently sound environmental factors that the pro- 
tocols depend on. As discussed below, our EPR-based protocol is semi-loss-tolerant because 
our bias decreases with the decreasing degree of losses in the quantum memory storage. 

3 EPR-BASED SEMI-LOSS-TOLERANT PROTOCOL 

As the first one providing a loss-tolerant SCF, Berlin et a/.'s protocol [20 proves that there 
exist quantum coin flipping protocols outperforming classical ones when taking losses into 
account. However, it achieves a relatively poor bias compared with previous loss-intolerant 
protocols. After deliberate consideration, we note that a key factor leading to the relatively 
high bias in Berlin et aVs protocol is that the two parties' bases may be inconsistent. As 
we know, the basis of measurement is randomly selected by Bob at step 2 in the original 
protocol(see Ref. [20]). If the basis is inconsistent with the one that Alice announces, Alice's 
possible cheating action can't be discovered by Bob, no matter what measurement result Bob 
gets. We suppose it will cut Alice's bias down if we keep Bob's basis always consistent with 
Alice's. 

To achieve our goal, we let Bob measure the qubit after Alice announces her basis. If Bob 
detects his qubit and finds nothing wrong with Alice, the outcome of the SCF is successfully 
generated. If he doesn't detect it, we let the protocol continue to generate the outcome rather 
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than restart, in case of Bob's always successful cheating strategy that he claims detecting 
nothing if he doesn't like the outcome. Here we present the revised qubit-based protocol: 

1. Alice prepares one state \(pa.rA) from { |i^o,o) = |0), \vos} = |1), Wi.'a) — cosq:|0) + 
sinajl), jiySi,!) = sinajO) — cosajl) } with basis a and bit ta chosen independently at 
random, and then she transmits it to Bob. 

2. Bob keeps the received qubit in his quantum memory storage (instead of immediately 
measures it as described in Ref. [20, ) . 

3. Bob sends a randomly chosen bit h to Alice. 

4. Alice reveals her original a and ta to Bob. 

5. Bob measures the qubit in the quantum memory according to Alice's announcing a. If 
he detects it, whose outcome is denoted as tb, and finds that ta^tb, he aborts the 
protocol, calling Alice a cheater. If ta = "Tb or even he doesn't detect the qubit, the 
outcome of the coin flipping is h® r a- 

In this protocol, although the two parties bases are kept consistent, a new problem occurs: if 
Bob doesn't detect the qubit in his quantum memory, he doesn't know whether the qubit is 
lost in his quantum memory or in the channel, or even the qubit hasn't been sent by Alice at 
all. As we know, Bob can't tell whether the qubit is definitely received without measurement. 
Using this fact, Alice can always succeed in cheating by sending nothing to Bob. To prevent 
from such attack and keep other properties of our protocol unchanged as much as possible, 
here we utilize an EPR pair to replace the original qubit. The following is our EPR-based 
protocol: 

1. Bob prepares a singlet |(p) = ^ "^'^ fk ^ where the subscripts A and B denote the 
two entangled particles, then he sends particle A to Alice. 

2. Alice randomly selects a classical bit a, where a = represents that she chooses basis 
{ \y) = |0), \y^) = |1) } and a = 1 represents that she chooses basis { \H) — cosa|0) + 
sina|l), l^""") — sinajO) — cosa|l)(0 < a < |)}, then she measures particle A along the 
basis she chooses. In the following discussions let |Va) and \iiA) correspond to ta — 0, 
and |V^) as well as \il^ correspond to r a = 1, where ta denotes the outcome of Alice's 
measurement. The same principle applies to Bob's later measurement, that is, \Vb) and 
\Hb) correspond to rs = 0, and |V^) as well as \Hg) correspond to r^ = 1, where r_B 
denotes the outcome of Bob's measurement. 

3. If Alice successfully detects the particle, she asks Bob to proceed the protocol, otherwise, 
she asks Bob to restart the protocol. 

4. Bob sends Alice a randomly selected classical bit b. 

5. Alice informs Bob of her selected a and outcome r^. 

6. Bob measures particle B along the basis that a represents. If he successfully detects 
it and finds va — tb, he will abort and claim Alice is cheating. In all other cases the 
outcome of the coin flipping is given by b(B ta- 
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In this protocol, Alice's measurenient on her part of the EPR pair collapses Bob's part to a 
random state known to herself. In this case, Bob can always make sure that his part, which 
is equivalent to the qubit sent by Alice in the above qubit-based protocol, is definitely stored 
in his quantum memory storage, no matter whether it is lost in the quantum memory or not. 
And Alice's measurement in the EPR-based protocol can be regarded as the process that 
she randomly sends a qubit to Bob and Bob then detects whether it is successfully received 
without measurement. As we know, the later action can't be realized and we just utilize the 
EPR pair to achieve the same goal. 

Let's sum up our analysis process. In order to cut down the bias in Berlin et al.'s 
protocoipD], we firstly let Bob measure the qubit after Alice announces her basis, keeping 
the two parties' bases consistent. After this revision, a new attack occurs: Bob can always 
succeed in cheating by the strategy that he claims detecting nothing if he doesn't like the 
outcome. We solve this threat by letting the protocol continue to generate the outcome even 
if Bob fails to detect the qubit. After this revision, however, another problem occurs: Alice 
can always succeed in cheating by sending nothing to Bob. Here we utilize an EPR pair to 
prevent from such attack. Note that we don't specify the value of a but regard it as a free 
parameter, which is to be adjusted to make the protocol fair. More details of their cheating 
strategies will be given in the following parts. 

4 ALICE'S MAXIMAL BIAS 

Since our protocol is symmetrical for the two outcomes, any cheater enjoys the same difficulty 
in biasing the outcome to or 1. 

It seems that Alice can cheat by claiming that she misses the particle when she is un- 
satisfied with her outcome at step 3. However, since b has not been given at that time and 
H{b © taIta) — 1, it's meaningless to bias r^ to any value. A more general strategy is that 
before step 4, she can perform a two-outcome positive operator-valued measure(POVM) with 
elements E'q and E'l ~ I — Eq on the received particle, trying to collapse the EPR pair to a 
certain state, without loss of generality, /3{y^E^ <g) I)\ip). Here /3 = w /o|_E-'|o)+(i|g»|i) ^^ ^^'^ 
normalization factor. And she can also claim that the particle is lost when she is unsatisfied 
with the outcome. To simplify the notation, let's define \ip*) — f3{yn^(^I)\ip), which denotes 
the combined quantum state after step 3. 

At step 5, she can announce a proper ta after b is given to get the right r^ © & that she 
wants. Besides, her only worry must be Bob's outcome tb in the last step. To pass Bob's test, 
she should bias rs to the proper value through her optimal measurement and announcement 
of her selected a. 

Without loss of generality, assume Alice wants to bias the outcome to 1, then let's discuss 
two cases. The first case is Bob announces b — I, then Alice is clear that she should declare 
that rA = l©&=l©l = and she wants to bais Bob's r^ to r^i © 1 = ffi 1 = 1. Therefore 
Alice should perform another two-outcome POVM measurement with elements ii^^"*'" and 
j^rA,a(B _ J jT;'^A,a j^^^ bcforc Step 5. After her measurement, she should inform Bob of 
a = oo and r^i = if her result is associated with E-^'"" , while inform Bob of a = ag © 1 
and r^i = if her result is associated with E{' . Here a^ is a Boolean parameter defined 
by Alice. Without loss of generality, let ao — 0, then the probability that Alice's result is 
associated with E{ equals P^a.a — {ip*\E{ ® I\'^*), and the composite state after measure- 
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ment is — — ^ . While the probability that Alice's result is associated with _Ei ' equals 

-lO.l ' 



Pgo.i — {if*\E-y' ®I\ip*), and the composite state after measurement is — — ^ . If Bob 



successfully detects his particle, the probability that he gets r^ — 0, which implies that Alice 
succeeds in cheating, after his measurement according to Alice's claiming a is given by 



PSI - PeO.o ) iI^\VB){VB\) ^ + (1) 

(^*|(i?r ® \Vb){Vb\W) + {v*\{El^' ® \Hb){Hb\W) 



Insert |(/?*) = ^J1^ ® I\lp) and E{ ^ I — E{ to above expression, we get 

'' {0\E*\0) + {1\E*\1) ^^ 

In the other case, Bob announces 6 = 0, let's assume Alice performs POVM measurement 
with elements El^'" = i;"'" and El^'"®^ = E^'^ = I ~ E^'" just before step 5. Similarly, we 
can obtain that the probability that Alice succeeds in cheating is given by 

p ^ {Va\^e",^'^\Va) - {Ha\^e','^\Ha} + {Ha\E*o\Ha) 
'' {0\E*\0) + {1\E*\1) ^> 

Note the two cases (i.e. Bob announces b ~ and 6=1) happens with the same probability 
2 , combining them together, we obtain the probability that Alice succeeds in cheating is given 



by 



Ps = ^^^^^ (4) 



Clearly, Alice wants to maximize Pg in order to increase her probability to succeed. Us- 
ing numerical method, we firstly fix a then randomly select 10^ qualified {Eq,Eq' ,E{ )s 
to test the value of Ps. Then we find Ps will get its maximum value if [Eq.Eq ,E{ ) = 
(/, |AS^''^)(A[;^"^|,|A7"^)(A7"^|) with |AJ^'^^)(|A7"^^)) being the maximum eigenvalue of the 
operator \Va){Va\ - \HA){HA\i\V^){V^\ - \H^){H^\) and AJ,"'^^(A7'^^) is the corresponding 
eigenstate. 

After simple calculation, we find A?,"""' = XY"""" = sin a, together with (^(J, £;°'°, S°'") = 
(/, |A[)"°^)(AS"''^|, |A7''^)(A7''^|), we obtain 

Ps = ^^° + ^^^ (5) 
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So the maximal probability that Alice passes Bob's test if Bob successfully detects his particle 
equals p™"^ — smo+i j|- j-gniains to analytically prove that the maximum value of Pg is 
5isf±i and it remains to figure out whether {E*,E°-°, E°'") = (/, |AS"""=)(AJJ"'^|, |Af''^)(Af''="|) 
is the only optimal solution. 

However, if Bob doesn't detect his check particle, our protocol still proceeds, and in such 
a case. Bob misses the chance to detect Alice's possible cheating and a dishonest Alice will 
definitely succeed. To combine the two cases together, let p{0 < p < 1) denote the probability 
that Bob fails to detect particle B, then the maximum probability that Alice succeeds is given 

by 



p^^ao, ^ (1 - p) X P^'''^ + p X 1 (6) 

sin a + 1 
(1 - P) X + 

1 + p + {1 — p) sin a 



,_, , sina + 1 
= (I-Pjx +pxl 



2 
Thus the maximum bias for Alice equals 

^max _ P+(l-p)sina 



(7) 



Comparing Alice's bias in our protocol with that in Ref. [20], let e'^ and e^ respectively 
denote Alice's bias in our protocol and that in [20], we have 

AeA = 6^^-6f (8) 

p + {1 — p) sin a 1 + sinct 

2 4 

(2p- l)(l-sina) 
4 

li p < |, that means the quantum memory is good enough, then Ae^ < 0, which means 
Alice's bias is successfully cut down by our revisions. 

5 BOB'S MAXIMAL BIAS 

Assume Bob wants to bias the outcome to 0, the most general cheating strategy for him is to 
firstly choose b to be sent at step 4 and then prepare an entangled state \lp') instead of \if) so 
that the probability that Alice's ta equals & ® will reach the maximum. 

Without loss of generality, assume Bob selects 6 = and prepares \ip') — ^/X\H'^)\Vg) + 
^/l — X\H'^ )\Vq )(| < a < 1), where |(^') is written in its Schmidt decomposition form 
and \H'^) =cos/3|0)+sin/3|l),|i/;^-^) = sin/3|0) - cos/?|l)(0 < /3 < f),while \V^) and 1^^"^) 
represent some choice of orthogonal states on Bob's space. Thus the state of particle A can 
be written as pA ~ A|i/^)(_ff^| + (1 — A)|iJ^ )(-H^a I- Since Alice is honest, she will carry out 
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the measurement on the particle according to a she randomly selects. Then the probability 
that she gets r^ = ® = 0, which implies that Bob succeeds in cheating, is given by 

Pb = ^{Va\pa\Va) + 1{Ha\pa\Ha) (9) 

_ 1 (2A- l)cosacos(a-2/3) 
2 ^ 2 



< 



1 cos a 

2 + — 



This bound can be saturated iff A = 1 and /3 = f . In this case \ip') = 1-^^)1^^), which is 
a product state so that \Vg) is unnecessary for Bob. In conclusion, the best cheating strategy 
for Bob is to send |i?^) — cos ^|0) + sin ^\1) to Alice at step 1 and then claims 5 = at step 
3, then the probability that he succeeds in biasing the outcome to equals P^°-^ = 5 + ^^-^, 
and the maximal bias for Bob equals 

We notice that by this strategy. Bob losses the chance to check Alice's cheating because 
he has no check particle to be entangled with the particle sent to Alice. However, this is not 
a flaw for Bob in our protocol, since we don't consider the situation when the two parties 
are simultaneously dishonest. Also note that Bob's bias is equal to that in Berlin et al.^s 
protocol[2D], which means our revisions have no effects on Bob's bias. 

6 FAIR SCENARIO 

To make our protocol fair we must adjust the free parameter a so that 

max max /'I 1 ^ 

^A — '^B U^J 

Inserting Eq.(7) and Eq.(lO) into Eq.(ll), we must have 

p + (l — p) sin a cos a 
2 ^ 2 

Solving for a in terms of p we get 



(12) 



. P^-P+V2^^ ,_,„. 

a = arcsm t^ — (13) 

By implying Eq.(13) to Eq.(7) and Eq.(lO), we get the bias in the fair scenario, which is given 
by 



e(p) = e™- = eT- = ^./^ o2^ o^ (14) 



P +{1- pW2 - 2 p 
2(p2 -2p + 2) 

We find that the maximal fair basis e{p) monotonously decreases as p decreases(see Fig.fTl), 
which means the more likely Bob successfully detects his particle, the securer the protocol 
can be. From the definition given in Sec. 2, we can call our protocol semi- loss-tolerant. 
This characteristic is totally different from all the loss-tolerant protocols whose biases are 
independent of the degree of the losses. 
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Fig. 1. Maximal fair bias is a function of p, it decreases with decreasing p, and our optimal bias 
outperforms all the previous ones. 



Comparing our bias with the previous loss-tolerant ones, we notice that e(0.5) = 0.4, 
e(0.457) = 0.395 and e(0.072) = 0.359, which respectively represents biases in Refs. [20l [22l 
[53]. In particular, e(0) — 0.3536, which means if the quantum memory storage approaches 
perfect, we can achieve a lower bias, 0.3536(see Fig. fl]). Also note that even if p = 0.5, that 
means the quantum memory is not very reliable, our protocol can still achieve the bias 0.4. 

7 EXPERIMENTAL ISSUES 

We have to admit that the improved performance relative to previous protocols only occurs 
when the degree of losses in the quantum memory is small enough. For example, to be better 
than bias 0.359 in Ref . [23' , the loss rate p of the quantum memory in our protocol must be 
less than 7.2%. Fortunately, entangled trapped atom-photon systems display the required 
behavior. It has been experimentally demonstrated by Blinov et al. 24J that using entangled 
trapped atom-photon systems can help us realize the process of EPR generation, transmis- 
sion and storage that are required in our protocol. Specifically, the transmitted particle in 
our protocol can be realized by the polarization of the emitted photon, while another one 
stored in the quantum memory can be represented by the internal atomic qubit levels, stored 
in ^5*1 hyperfine ground states. Experiment results has shown that the success probability 
of detecting the transmitted photon is P ~ 1.6 x 10^''. The experiment repetition rate is 
R < 2x 10^s~^, resulting in an entanglement generation rate Ri = PR < 0.3s~^. That means 
in our protocol, Alice is expected to detect the particle within j^„L^ ~ 3.3s. What's more, the 
coherence time of trapped ion is very long and the loss of ion quantum memory is negligible 
for practical applications. That means the sufficiently small loss rate of the quantum memory 
required in our protocol can be achieved. Taking the efficiency with which the state of the 
quantum memory can be read out, which is almost 100%, into consideration, we obtain the 
total efficiency of our protocol is almost i?™"^ x 100% — 0.3s^^. 
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Although not the main concern of this paper, the fidehty of such a memory will inevitably 
influence the performance of our protocol. As we know, an imperfect fidelity will create errors, 
which will decrease the storage time. Hence, the longer is the distance between Alice and 
Bob, the longer will the required storage time be, and the higher will the error rate be. 

Considering the motivation behind the introduction of loss-tolerant protocols is experi- 
mental, our scenario has been theoretically demonstrated experimentally feasible. Recently, 
Berlin et al. Ref. |25j implemented the first experimental demonstration of a loss-tolerant 
quantum coin flipping protocol using single qubits, and we are interested to see practical 
realizations of such a protocol with EPR pairs. 

8 CONCLUSION 

We have presented an EPR-based semi-loss-tolerant SCF protocol, and the novelties in our 
manuscript can be summarized as: 

1. We have proposed a novel approach to solve the issue implied in Ref. [5^, i.e., the two 
parties' bases may be inconsistent, which we think is a key factor that leads to the 
relatively higher bias in Ref. [20] . 

2. We introduce the EPR pair to prevent Alice's sending-nothing cheating strategy. 

3. As one of the most important indicator in a CF, the bias in our protocol performs 
better than the previous loss-tolerant ones in the presence of sufficiently small losses in 
the quantum memory storage. 

4. We find our bias varies with the change of the losses degree of the quantum memory 
storage, while the bias is independent to the losses in the quantum channel just like the 
previous loss-tolerant CF protocols. This proves that there exist semi-loss-tolerant CF 
protocols that are sensitive to losses in the quantum memory storage. 

5. This is the first manuscript taking the losses in the quantum memory into account. As 
discussed in Sec VII of Ref. 01], when introducing a loss-tolerant WCF protocol, "it 
would seem that a major difBculty is that at the end of a WCF protocol the losing 
party usually verifies the outcome by measuring a quantum system that has been kept 
in a quantum memory storage. Hence, in this scenario the losing party can always 
avoid losing by claiming to have lost the stored system" . We suppose that step 6 in our 
EPR-based protocol provides significant inspiration to this problem. 

6. We discussed that since trapped ions' state can be read-out with almost 100% efficiency, 
implementing our protocol with a trapped ion entangled with a single photon makes 
our proposal potentially feasible in practice. Also, we demonstrated that losses in the 
transmission channel only affect the efficiency instead of the bias of our protocol. 

Moreover, there is still a problem when implementing this protocol. Before starting the 
protocol, Alice and Bob must negotiate to choose a proper a according to p and Eq.(13). The 
question is how to obtain the real p, which is a parameter of Bob's machine. If p is claimed 
by Bob himself, he can cheat by claiming a relatively larger value than the real pq. In such 
a case, Alice's bias cb equals e{po), while Bob's bias e^ is actually larger than e(po)- That 
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means the protocol is actually unfair. A possible way to solve this problem is that Alice sets 
a threshold for p, if Bob's announcing p surpasses the threshold, she will refuse to implement 
the protocol with Bob. 
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